Method of controlling biometric authentication system, non-transitory, computer readable storage medium and biometric authentication system
Summary by NHIP
Dynamic Biometric Matching Location
The system calculates a user's authentication success rate from stored historical results to decide where matching occurs. If the rate meets a threshold, the server performs matching; otherwise, it sends reference data to the client for local calculation.
Claim Score by NHIP
Abstract
A control method for controlling a biometric authentication system including a server that stores reference biometric data, and a client that acquires biometric authentication data of the user, has saving in the server a table in which identification information identifying the user and a previous authentication result of the user are associated with each other, transmitting the identification information to the server, referring to the identification information and acquiring a previous authentication result of the user corresponding to the identification information from the table, calculating, an authentication success rate of the user from the acquired previous authentication result, transmitting the reference biometric data to the client when the authentication success rate is less than or equal to a certain value, calculating, a degree of matching between the biometric authentication data and the reference biometric data, and determining, whether or not the authentication of the user has succeeded.

Term
Projected expiry 18 September 2029.
- Priority
- Filed
- Granted
- Today
- Projected expiry
13 claims: 3 independent, 10 dependent
- 1A control method of controlling a biometric authentication system including a server that stores reference biometric data used as a reference for authentication of a user, and a client that acquires biometric authentication data from the user, the control method comprising:saving, in the server, associated information in which identification information identifying the user and a previous authentication result of the user are associated with each other;transmitting the identification information identifying the user to the server from the client;referring to, at the server, the identification information transmitted from the client and acquiring a previous authentication result of the user corresponding to the identification information from the saved associated information;calculating, at the server, an authentication success rate of the user from the acquired previous authentication result;determining, at the server, to calculate a degree of matching at the client when the calculated authentication success rate does not satisfy a threshold, and to calculate the degree of matching at the server when the calculated authentication success rate satisfies the threshold;transmitting, when said determining determines to calculate the degree of matching at the client, the reference biometric data from the server to the client and then calculating, at the client, the degree of matching between the biometric authentication data and the reference biometric data transmitted from the server, so that the degree of matching is thereby calculated at the client when the authentication success rate does not satisfy the threshold;and determining, based on the degree of matching calculated at the client, whether or not the authentication of the user has succeeded.
- 6A non-transitory, computer readable storage medium storing a program to control a biometric authentication system including a server that stores reference biometric data used as a reference for authentication of a user, and a client that acquires biometric authentication data from the user, the program, when executed, causes the biometric authentication system to perform a process comprising:saving, in the server, associated information in which identification information identifying the user and a previous authentication result of the user are associated with each other;transmitting the identification information identifying the user to the server from the client;referring to, at the server, the identification information transmitted from the client and acquiring a previous authentication result of the user corresponding to the identification information from the stored associated information;calculating, at the server, an authentication success rate of the user from the acquired previous authentication result;determining to calculate a degree of matching at the client when the calculated authentication success rate does not satisfy a threshold, and to calculate the degree of matching at the server when the calculated authentication success rate satisfies the threshold;when said determining determines to calculate the degree of matching at the client, transmitting the reference biometric data from the server to the client, and calculating, at the client, the degree of matching between the biometric authentication data and the reference biometric data transmitted from the server, so that the degree of matching is thereby calculated at the client when the authentication success rate does not satisfy the threshold;and determining, based on the degree of matching calculated at the client, whether or not the authentication of the user has succeeded.
- 7Broadest claimClaim Score 45, average(NHIP)A biometric authentication system comprising:a server that stores reference biometric data used as a reference for authentication of a user;and a client that acquires biometric authentication data from the user, the server including a storage unit to store associated information in which identification information identifying user and a previous authentication result of the user are associated with each other, a calculating unit to refer to the identification information and the stored associated information, to calculate an authentication success rate of the user from a previous authentication result of the user corresponding to the identification information, and to determine to calculate a degree of matching at the client when the calculated authentication success rate does not satisfy a threshold and to calculate the degree of matching at the server when the calculated authentication success rate satisfies the threshold, and a transmitting unit to transmit the reference biometric data to the client when the calculating unit determines to calculate the degree of matching at the client, the client including a determining unit to, when the calculating unit of the server determines to calculate the degree of matching at the client, calculate the degree of matching between the biometric authentication data and the reference biometric data, which is transmitted from the server to the client, and to determine, based on the degree of matching, whether or not the authentication of the user has succeeded, so that the degree of matching is thereby calculated at the client when the authentication success rate does not satisfy the threshold.
Independent claims3
122 paragraphs in 6 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION
0001This is a continuation of Application PCT/JP2009/004775, filed on Sep. 18, 2009, the entire contents of which are incorporated herein by reference.
FIELD
0002The present art relates to a biometric authentication system and a control method.
BACKGROUND
0003There is a client-server biometric authentication system. A client acquires biometric data of a user. A server holds a registered template used as a reference for the authentication of the user. Upon receipt of an authentication request from a client, a server performs a verification process between biometric data for verification, which has been transmitted from the client, and a registered template held in the server. If the degree of matching between the biometric data and the registered template, which has been calculated in the verification process, is greater than or equal to a threshold, the server authorizes the client to access the system. A client-server biometric authentication system can manage access to a server by allowing the server to manage authentication results as a log.
0004In biometric authentication, a server may use a plurality of algorithms when verifying the identity of an individual. For example, when verifying the identity of an individual, the server firstly performs verification based on minutiae points. If the degree of matching is greater than or equal to a threshold, the identity is verified and access to the system is authorized. If the degree of matching obtained in the verification based on minutiae points is less than or equal to the threshold, the server further performs a pattern matching process. When the degree of matching obtained in the pattern matching process is greater than or equal to a threshold, access to the system is authorized.
0005For users who are difficult to authenticate, the server needs to perform a pattern matching process in addition to a verification process based on minutiae points. Thus, the amount of computation to be performed by the server increases, and the authentication process time becomes long. In addition, because of the increase in the amount of computation in a fingerprint authentication process to be performed by the server on a user who is difficult to authenticate, a concentration of authentication requests from users who are difficult to authenticate to the server causes an increase in the load on the server (see, for example, Japanese Laid-open Patent Publication No. 09-288648 and Japanese Laid-open Patent Publication No. 2005-182641).
SUMMARY
0006According to an aspect of an embodiment, a control method for controlling a biometric authentication system including a server that stores reference biometric data used as a reference for authentication of a user, and a client that acquires biometric authentication data from the user, the control method has saving in the server a table in which identification information identifying the user and a previous authentication result of the user are associated with each other, transmitting the identification information identifying the user to the server from the client, referring to, at the server, the identification information transmitted from the client and acquiring a previous authentication result of the user corresponding to the identification information from the table, calculating, at the server, an authentication success rate of the user from the acquired previous authentication result, transmitting the reference biometric data from the server to the client when the authentication success rate is less than or equal to a certain value, calculating, at the client, a degree of matching between the biometric authentication data and the reference biometric data transmitted from the server, and determining, based on the degree of matching, whether or not the authentication of the user has succeeded.
0007The object and advantages of the invention will be realized and attained by means of the elements and combinations particularly pointed out in the claims.
0008It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory and are not restrictive of the invention, as claimed.
BRIEF DESCRIPTION OF DRAWINGS
0009<figref idref="DRAWINGS">FIG. 1</figref> is a diagram illustrating a biometric authentication system (part <b>1</b>) according to this embodiment.
0010<figref idref="DRAWINGS">FIG. 2</figref> is a diagram illustrating a user management table.
0011<figref idref="DRAWINGS">FIG. 3</figref> is a diagram illustrating a log of verification results.
0012<figref idref="DRAWINGS">FIG. 4</figref> is a diagram illustrating a client management table.
0013<figref idref="DRAWINGS">FIG. 5</figref> is a diagram illustrating a biometric authentication system (part <b>2</b>) according to this embodiment.
0014<figref idref="DRAWINGS">FIG. 6</figref> is a diagram illustrating a client management table.
0015<figref idref="DRAWINGS">FIG. 7</figref> is a diagram illustrating a client management table.
0016<figref idref="DRAWINGS">FIG. 8</figref> is a diagram illustrating a biometric authentication system (part <b>3</b>) according to this embodiment.
0017<figref idref="DRAWINGS">FIG. 9</figref> is a diagram illustrating a biometric authentication system (part <b>4</b>) according to this embodiment.
0018<figref idref="DRAWINGS">FIG. 10</figref> is a diagram illustrating a user management table.
0019<figref idref="DRAWINGS">FIG. 11</figref> is a diagram illustrating changes in authentication success rate.
0020<figref idref="DRAWINGS">FIG. 12</figref> is a flowchart (part <b>1</b>) depicting an authentication process according to this embodiment.
0021<figref idref="DRAWINGS">FIG. 13</figref> is a flowchart (part <b>2</b>) depicting an authentication process according to this embodiment.
0022<figref idref="DRAWINGS">FIG. 14</figref> is a flowchart (part <b>3</b>) depicting an authentication process according to this embodiment.
DESCRIPTION OF EMBODIMENT
0023<figref idref="DRAWINGS">FIG. 1</figref> illustrates a biometric authentication system <b>0</b> according to this embodiment. The operation during authentication is represented by broken line arrows in <figref idref="DRAWINGS">FIG. 1</figref>. The biometric authentication system <b>0</b> includes a client <b>100</b> and an authentication server <b>200</b>. The client <b>100</b> includes a data acquisition unit <b>102</b>, a verification processing unit <b>104</b>, a verification result acquisition unit <b>106</b>, and a log saving unit <b>108</b>. The authentication server <b>200</b> includes a user management table <b>300</b>, a verification processing unit <b>204</b>, a verification result acquisition unit <b>206</b>, a log saving unit <b>208</b>, a tendency extraction unit <b>210</b>, and an operating policy control unit <b>212</b>.
0024The data acquisition unit <b>102</b> acquires a user ID and data for verification, which is used in biometric authentication, and transmits the user ID and the data for verification to the authentication server <b>200</b>. The verification processing unit <b>104</b> calculates the degree of matching between the data for verification and a registered template transmitted from the authentication server <b>200</b>, and for determining, based on the degree of matching, whether or not the associated user has succeeded in the authentication. The verification result acquisition unit <b>106</b> acquires the verification result for the user obtained by the verification processing unit <b>104</b>, and saves the verification result in the log saving unit <b>108</b>.
0025The verification processing unit <b>204</b> calculates the degree of matching between the data for verification, which is transmitted from the client <b>100</b>, and a registered template, and for determining, based on the degree of matching, whether or not the user has succeeded in the authentication. The verification result acquisition unit <b>206</b> acquires the verification result for the user obtained by the verification processing unit <b>204</b>, and saves the verification result in the log saving unit <b>208</b>. The tendency extraction unit <b>210</b> calculates the authentication success rate of each user for a certain period from log information saved in the log saving unit <b>208</b> in order to determine a user who is difficult to authenticate. The operating policy control unit <b>212</b> instructs the tendency extraction unit <b>210</b> to periodically extract the tendency of authentication results for each user from the log information saved in the log saving unit <b>208</b> in order to identify a user who is difficult to authenticate.
0026<figref idref="DRAWINGS">FIG. 2</figref> illustrates an example of the user management table <b>300</b>. The user management table <b>300</b> has a user ID <b>302</b>, a registered fingerprint template <b>304</b>, a fingerprint data type <b>306</b>, a registration quality <b>308</b>, and a local-authenticated-user flag <b>310</b>.
0027The user ID <b>302</b> is an ID of a user who performs biometric authentication. The registered fingerprint template <b>304</b> is data that is registered in advance by a user and that is used as a reference for biometric authentication. The fingerprint data type <b>306</b> is a type of data to be used in biometric authentication. The registration quality <b>308</b> is the quality of the registered fingerprint template <b>304</b>. In this embodiment, when the registered fingerprint template <b>304</b> is registered, biometric data of the user is acquired in a plurality of number of times and the registered fingerprint template <b>304</b> is generated from the acquired data. For example, if the fingerprint of the user is in good condition, every acquired piece of biometric data has a high degree of matching. Accordingly, the quality is defined to be high when the degree of matching between the acquired pieces of biometric data is high. The local-authenticated-user flag <b>310</b> is a flag indicating which of server authentication and local authentication to apply for each user.
0028The authentication server <b>200</b> is capable of determining which of server authentication and local authentication to apply for each user by referring to the local-authenticated-user flag <b>310</b>.
0029The data acquisition unit <b>102</b> of the client <b>100</b> acquires a user ID and data for verification, which is used in biometric authentication, and transmits the user ID and the data for verification to the authentication server <b>200</b>. The authentication server <b>200</b> refers to the local-authenticated-user flag <b>310</b> included in the user management table <b>300</b> illustrated in <figref idref="DRAWINGS">FIG. 2</figref>, based on the user ID transmitted from the client <b>100</b>. The authentication server <b>200</b> determines whether to perform server authentication or local authentication on the corresponding user. If server authentication is to be performed on the corresponding user, the verification processing unit <b>204</b> performs a verification process between a registered template and the data for verification. The verification result acquisition unit <b>206</b> acquires a verification result, and saves a log of the verification result in the log saving unit <b>208</b>. On the other hand, if local authentication is to be performed on the corresponding user, the authentication server <b>200</b> transmits the user ID, the data for verification, and the registered template to the client <b>100</b>. The verification processing unit <b>104</b> of the client <b>100</b> performs a verification process between the registered template and the data for verification. The verification result acquisition unit <b>106</b> acquires a verification result, and saves a log of the verification result in the log saving unit <b>108</b>. When local authentication is performed, the client <b>100</b> transmits an authentication result to the log saving unit <b>208</b> of the authentication server <b>200</b> in a way synchronous or asynchronous to the authentication time.
0030Here, <figref idref="DRAWINGS">FIG. 3</figref> illustrates an example of a log <b>400</b> of verification results. The log <b>400</b> of verification results is a table having a date and time <b>402</b>, a user ID <b>404</b>, a client name <b>406</b>, an IP address <b>408</b>, an authentication type <b>410</b>, a biometric data type <b>412</b>, an authentication program version level <b>414</b>, a verification algorithm <b>416</b>, a verification score <b>418</b>, and an authentication result <b>420</b>.
0031The date and time <b>402</b> indicates the date and time when biometric authentication was performed. The user ID <b>404</b> indicates the ID of a user who performed biometric authentication. The client name <b>406</b> indicates the name of a client that performed biometric authentication. The IP address <b>408</b> indicates the IP address of a client that performed biometric authentication. The authentication type <b>410</b> indicates a method of biometric authentication. The biometric data type <b>412</b> indicates a type of biometric information used in biometric authentication. The authentication program version level <b>414</b> indicates the version of a program under which authentication is performed. The verification algorithm <b>416</b> indicates a verification algorithm used in biometric authentication. In this embodiment, first, verification is performed using minutiae points of biometric data. Then, for a user whose identity has not been successfully verified only with the minutiae points, verification is performed using pattern matching of biometric data. The verification score <b>418</b> is a value indicating the score to be referred to for determining whether to perform automatic switching to local authentication, and is a value indicating the degree to which the registered template and the data for verification match. The authentication result <b>420</b> indicates authentication success or failure.
0032An exemplary implementation of operation when dynamically controlling an operating policy as to which of local authentication and server authentication to apply is indicated by solid line arrows in <figref idref="DRAWINGS">FIG. 1</figref>. The operating policy control unit <b>212</b> instructs the tendency extraction unit <b>210</b> to periodically extract the tendency of authentication results for each user from the log <b>400</b> of verification results in order to identify a user who is difficult to authenticate. In this embodiment, the operating policy control unit <b>212</b> instructs the tendency extraction unit <b>210</b> to calculate an authentication success rate of each user for a certain period from the log information in order to identify a user who is difficult to authenticate. The operating policy control unit <b>212</b> may identify a user who is difficult to authenticate by using the average value of verification scores obtained for a certain period or using information on an algorithm used for verification.
0033The tendency extraction unit <b>210</b> calculates an authentication success rate of each user for a certain period from previous authentication results of the user by referring to the log <b>400</b> of verification results. If the authentication success rate is greater than or equal to a threshold, the operating policy control unit <b>212</b> changes the local-authenticated-user flag <b>310</b> in the user management table <b>300</b> in order to perform server authentication. If the authentication success rate is less than or equal to the threshold, the operating policy control unit <b>212</b> changes the local-authenticated-user flag <b>310</b> in the user management table <b>300</b> in order to perform local authentication.
0034In the example illustrated in <figref idref="DRAWINGS">FIG. 2</figref>, furthermore, the operating policy control unit <b>212</b> can specify local authentication on a user-by-user basis. However, the operating policy control unit <b>212</b> may specify local authentication on a client-by-client basis. In order to specify local authentication on a client-by-client basis, the authentication server <b>200</b> may have a client management table <b>700</b> illustrated in FIG. <b>5</b>. The client management table <b>700</b> has a client name <b>702</b>, an IP address <b>704</b>, and a local-authenticated-user flag <b>706</b>.
0035In this embodiment, an example in which an authentication success rate is calculated for each user ID and the local-authenticated-user flag <b>310</b> included in the user management table <b>300</b> is updated has been illustrated. Additionally, the tendency extraction unit <b>210</b> may calculate an authentication success rate for each client, and the operating policy control unit <b>212</b> may set the local-authenticated-user flag <b>310</b> for each client. The operating policy control unit <b>212</b> periodically performs the above processes in batch processing, and dynamically controls an operating method by switching from server authentication to local authentication when the authentication success rate decreases and by switching from local authentication to server authentication when the authentication success rate increases.
0036In the biometric authentication system <b>0</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, the authentication server <b>200</b> has the user management table <b>300</b>, and determines whether to switch to local authentication by referring to the local-authenticated-user flag <b>310</b> in the user management table <b>300</b>. <figref idref="DRAWINGS">FIG. 5</figref> illustrates a biometric authentication system <b>2</b> for speeding up this process. In the biometric authentication system <b>2</b> illustrated in <figref idref="DRAWINGS">FIG. 5</figref>, the client <b>100</b> also has the user management table <b>300</b>. Elements corresponding to those described with reference to <figref idref="DRAWINGS">FIG. 1</figref> are assigned the same numerals, and a description thereof is omitted.
0037At the time of authentication, the data acquisition unit <b>102</b> of the client <b>100</b> acquires a user ID and data for verification, which is used in biometric authentication. Then, the client <b>100</b> refers to the user management table <b>300</b> by using the user ID acquired by the data acquisition unit <b>102</b>. The client <b>100</b> performs a verification process between the registered template owned by the client and the verification data if the corresponding user is to be authenticated using local authentication. The client <b>100</b> transmits the user ID and the data for verification to the authentication server <b>200</b> if the corresponding user is to be authenticated using server authentication. The process performed in the authentication server <b>200</b> is similar to the process of the biometric authentication system <b>0</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>.
0038If the corresponding user ID is not found in the user management table <b>300</b> owned by the client <b>100</b>, server authentication is performed. In the biometric authentication system <b>2</b> illustrated in <figref idref="DRAWINGS">FIG. 5</figref>, the client <b>100</b> is capable of determining which of server authentication and local authentication to perform. Therefore, quick switching to local authentication can be made at the time of authentication without using communication between the authentication server <b>200</b> and the client <b>100</b>.
0039An exemplary implementation of operation when dynamically controlling the operating policy in a case where the client <b>100</b> has the user management table <b>300</b> is indicated by solid line arrows in <figref idref="DRAWINGS">FIG. 5</figref>. The operating policy control unit <b>212</b> instructs the tendency extraction unit <b>210</b> to periodically extract the tendency of authentication results for each user from the log information in order to identify a user who is difficult to authenticate. Subsequently, similarly to the biometric authentication system <b>0</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, the tendency extraction unit <b>210</b> calculates an authentication success rate of each user for a certain period, determines whether to perform local authentication or server authentication, and updates the user management table <b>300</b> owned by the authentication server <b>200</b>.
0040The user management table <b>300</b> owned by the client <b>100</b> and the user management table <b>300</b> owned by the authentication server <b>200</b> need to be synchronized with each other. For this purpose, the authentication server <b>200</b> periodically transmits the user management table <b>300</b> to the client <b>100</b>. However, it is not acceptable for security reasons that all the pieces of user data held in the authentication server <b>200</b> are transmitted to the data registered in the client <b>100</b>. For this reason, there is a need to limit user information to be periodically transmitted to the client <b>100</b> from the authentication server <b>200</b>. Consequently, the authentication server <b>200</b> has a client management table <b>500</b> illustrated in <figref idref="DRAWINGS">FIG. 6</figref>, and limits the user information to be transmitted to the client <b>100</b>.
0041The client management table <b>500</b> has a client name <b>502</b>, an IP address <b>504</b>, a user ID <b>506</b>, an authentication type <b>508</b>, and an authentication program version level <b>510</b>. The authentication server <b>200</b> refers to the IP address <b>504</b> corresponding to the client identified by the client name <b>502</b>. Then, the authentication server <b>200</b> transmits user information to the client <b>100</b>. The client management table <b>500</b> can be created manually by a system administrator or may be periodically created from the log <b>400</b> of verification results. In addition, in order to achieve synchronization between the data owned by the client <b>100</b> and the data owned by the authentication server <b>200</b>, the client <b>100</b> periodically refers to the user management table <b>300</b> owned by the client <b>100</b>, and periodically downloads a registered template for only a user for local authentication from the authentication server <b>200</b> to make an update.
0042In the biometric authentication system <b>0</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref> and the biometric authentication system <b>2</b> illustrated in <figref idref="DRAWINGS">FIG. 5</figref>, first, the authentication server <b>200</b> calculates an authentication success rate of each user for a certain period in order to speed up the authentication process and reduce load. Then, a user who is difficult to authenticate, which will require a large amount of computation to authenticate, is identified, and a user to be authenticated with local authentication is set.
0043Further, an embodiment in which a user who is difficult to authenticate in biometric authentication is identified using the quality of a registered template and quality information about data for verification will be described. In a case where the quality of a registered template is used, in <figref idref="DRAWINGS">FIG. 1</figref> and <figref idref="DRAWINGS">FIG. 5</figref>, the tendency extraction unit <b>210</b> extracts a user for which the registration quality is less than or equal to a threshold from the user management table <b>300</b> when dynamically changing the operating policy. If the registration quality is less than or equal to the threshold, the operating policy control unit <b>212</b> changes the local-authenticated-user flag <b>310</b> in the user management table <b>300</b> to local authentication. If the registration quality is greater than or equal to the threshold, the operating policy control unit <b>212</b> changes the local-authenticated-user flag <b>310</b> in the user management table <b>300</b> to server authentication.
0044The local-authenticated-user flag <b>310</b> in the user management table <b>300</b> can also be changed when a user registers a registered template. In the user management table <b>300</b>, if one user ID has a plurality of registered templates, the average value of the registration qualities of the plurality of registered templates and the quality of registered data to be frequently used for verification from the log <b>400</b> of verification results may be calculated to determine whether to perform local authentication or server authentication. It is assumed that the threshold for the quality of registered data for determining whether to perform local authentication or server authentication is defined in the system.
0045Next, <figref idref="DRAWINGS">FIG. 8</figref> illustrates a biometric authentication system <b>6</b> for determining whether to perform local authentication or server authentication by using quality information about data for verification. Elements corresponding to those described with reference to <figref idref="DRAWINGS">FIG. 1</figref> and <figref idref="DRAWINGS">FIG. 5</figref> are assigned the same numerals, and a description thereof is omitted. The verification-data quality extraction unit <b>201</b> extracts the quality of data for verification, which has been transmitted from the client <b>100</b>.
0046At the time of authentication, the data acquisition unit <b>102</b> of the client <b>100</b> acquires a user ID and data for verification, which is used in biometric authentication, and transmits the user ID and the data for verification to the authentication server <b>200</b>. The verification-data quality extraction unit <b>201</b> of the authentication server <b>200</b> extracts the quality of the data for verification, which has been transmitted from the client <b>100</b>. If the quality of the data for verification is greater than or equal to a threshold, the verification processing unit <b>204</b> of the authentication server <b>200</b> performs a verification process between a registered template and the data for verification. The verification result acquisition unit <b>206</b> acquires a verification result, and saves a log of the verification result in the log saving unit <b>208</b>. On the other hand, if the quality of the data for verification is less than or equal to the threshold, a registered template is acquired from a user management table <b>900</b> illustrated in <figref idref="DRAWINGS">FIG. 7</figref>, and the authentication server <b>200</b> transmits the data for verification, the user ID, and the registered template to the client <b>100</b>.
0047Here, the quality of the data for verification will be described. For example, if a fingerprint of a user is in good condition, the ridge portions and the valley portions clearly appear in obtained data for verification. A binarization process is performed on the data for verification in which the ridge portions and the valley portions clearly appear to generate a density histogram representing the image density distribution, where peak values about the ridge portions and the valley portions also clearly appear. In this embodiment, data for verification in which peak values about the ridge portions and the valley portions clearly appear is defined as high-quality data.
0048If the local-authenticated-user flag <b>310</b> of the corresponding user represents local authentication, the authentication server <b>200</b> transmits the user ID, the data for verification, and the registered template to the client <b>100</b>. The verification processing unit <b>104</b> of the client <b>100</b> performs a verification process between the registered template and the data for verification. The verification result acquisition unit <b>106</b> acquires a verification result, and saves a log of the verification result in the log saving unit <b>108</b>. When local authentication is performed, the client <b>100</b> transmits the authentication result to the log saving unit <b>208</b> of the authentication server <b>200</b> in a way synchronous or asynchronous to the authentication time.
0049It is assumed that the threshold for determining whether to perform local authentication or server authentication is defined in the system. In addition, the client <b>100</b> may extract data for verification at the time of authentication and may transmit the quality of the data for verification together with the user ID and the data for verification to the authentication server <b>200</b>.
0050In the biometric authentication system <b>6</b> described above, a registered template is downloaded into the client <b>100</b> from the authentication server <b>200</b> and the client <b>100</b> performs a verification process. Thus, the registered template for a user may leak from a communication path, and the leakage of the registered template would introduce a risk of a spoofing attack. Since biometric information is basically invariable during the lifetime of the user although it may change over time, there is a risk of unauthorized access during the lifetime of the user by someone spoofing the user once the registered data leaks.
0051Now, a description will be given of cancelable biometric authentication in which in order to realize local authentication with high security maintained even if a registered template leaks, the registered template is transformed using a transformation key during automatic switching to local authentication and data for verification is also transformed using the transformation key to allow verification between the transformed pieces of data.
0052In this embodiment, if a registered template leaks, the transformation key is changed and a registered template is re-registered. Therefore, unauthorized access can be prevented.
0053The operation of a biometric authentication system <b>8</b> based on cancelable biometric authentication during authentication is represented by broken line arrows in <figref idref="DRAWINGS">FIG. 9</figref>. Elements corresponding to those described with reference to <figref idref="DRAWINGS">FIG. 1</figref>, <figref idref="DRAWINGS">FIG. 5</figref>, and <figref idref="DRAWINGS">FIG. 8</figref> are assigned the same numerals, and a description thereof is omitted. A transformation key creation unit <b>218</b> creates key information for transforming data. A verification data transformation unit <b>214</b> transforms data for verification using the key information created by the transformation key creation unit <b>218</b>. A registered-data transformation unit <b>216</b> transforms a registered fingerprint template using the key information created by the transformation key creation unit <b>218</b>.
0054The data acquisition unit <b>102</b> of the client <b>100</b> acquires a user ID and data for verification, which is used in biometric authentication, and transmits the user ID and the data for verification to the authentication server <b>200</b>. The authentication server <b>200</b> refers to a local-authenticated-user flag included in a user management table <b>600</b> from the user ID transmitted from the client <b>100</b>. If the corresponding user is to be authenticated using server authentication, the verification processing unit <b>204</b> performs a verification process between the registered template and the data for verification. The verification result acquisition unit <b>206</b> acquires a verification result, and saves a log of the verification result in the log saving unit <b>208</b>.
0055On the other hand, if the local-authenticated-user flag of the corresponding user represents local authentication, the verification data transformation unit <b>214</b> transforms the data for verification using the transformation key included in the user management table <b>600</b>. The authentication server <b>200</b> transmits the user ID, the transformed data for verification, and the transformed registered template to the client <b>100</b>. The verification processing unit <b>104</b> of the client <b>100</b> performs a verification process between the transformed registered template and the transformed data for verification. The verification result acquisition unit <b>106</b> acquires a verification result, and saves a log of the verification result in the log saving unit <b>108</b>. When local authentication is performed, the authentication result is transmitted to the log saving unit <b>208</b> of the authentication server <b>200</b> in a way synchronous or asynchronous to the authentication time.
0056<figref idref="DRAWINGS">FIG. 10</figref> illustrates an example of the user management table <b>600</b>. The user management table <b>600</b> has a user ID <b>602</b>, a registered fingerprint template <b>604</b>, a transformed registered fingerprint template <b>606</b>, a transformation key <b>608</b>, a fingerprint data type <b>610</b>, a registration quality <b>612</b>, and a local-authenticated-user flag <b>614</b>. The transformation key <b>608</b> is key information for transforming the registered fingerprint template <b>604</b>. The transformed registered fingerprint template <b>606</b> is a template produced by the registered-data transformation unit <b>216</b> transforming the registered fingerprint template by using the key information created by the transformation key creation unit <b>218</b>. The user management table <b>600</b> has a transformed registered template that has been created by the registered-data transformation unit <b>216</b> by using the transformation key produced in advance by the transformation key creation unit, thereby quickly realizing cancelable authentication at the time of authentication. It is assumed that cancelable biometric authentication can also be applied in the biometric authentication system <b>2</b>, the biometric authentication system <b>4</b>, and the biometric authentication system <b>6</b> described above.
0057An exemplary implementation of operation when dynamically controlling an operating policy as to which of local authentication and server authentication to perform in case of applying cancelable biometric authentication is indicated by solid line arrows in <figref idref="DRAWINGS">FIG. 10</figref>. The operating policy control unit <b>212</b> instructs the tendency extraction unit <b>210</b> to periodically extract the tendency of authentication results for each user from the log information in order to identify a user who is difficult to authenticate.
0058Subsequently, similarly to the biometric authentication system <b>0</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, the tendency extraction unit <b>210</b> calculates an authentication success rate of each user for a certain period, and determines whether to perform local authentication or server authentication. Then, the tendency extraction unit <b>210</b> updates the user management table <b>600</b> owned by the authentication server <b>200</b>.
0059In this embodiment, the transformation key creation unit <b>218</b> creates a transformation key only for a user to be authenticated with local authentication, and transforms the associated registered template. Then, the operating policy control unit <b>212</b> stores the transformed registered template and the transformation key in the user management table <b>600</b>. If it is determined that server authentication is to be performed, the operating policy control unit <b>212</b> deletes the transformed registered template and the transformation key from the user management table <b>600</b>. The operating policy control unit <b>212</b> periodically performs the above processes in batch processing, and dynamically controls an operating method.
0060This embodiment can also be applied to the biometric authentication system <b>2</b> in which the client <b>100</b> has the user management table <b>300</b> illustrated in <figref idref="DRAWINGS">FIG. 2</figref>.
0061Subsequently, the foregoing embodiment will be described specifically with reference to a diagram illustrated in <figref idref="DRAWINGS">FIG. 11</figref> which illustrates changes in the authentication success rate of a user. <figref idref="DRAWINGS">FIG. 11</figref> illustrates changes in the authentication success rate when User<b>0001</b> performed fingerprint authentication. The horizontal axis represents the time when the User<b>0001</b> performed fingerprint authentication. The vertical axis represents the authentication success rate of the User<b>0001</b>.
0062An embodiment will be described in which changing between local authentication and server authentication is based on the authentication success rate of each user. <figref idref="DRAWINGS">FIG. 11</figref> illustrates changes in the authentication success rate when the User<b>0001</b> performs fingerprint authentication. If it is assumed that the current month is January, the finger of the User<b>0001</b> is dry and thus the authentication success rate in December is reduced to 30%. Upon receipt of an authentication request from the User<b>0001</b>, the authentication server <b>200</b> performs a pattern matching process in addition to verification based on only minutiae points to verify the identity of the User<b>0001</b>. Accordingly, if an authentication request is issued from the User<b>0001</b>, the amount of computation increases, leading to an increased load on the authentication server <b>200</b>.
0063In this embodiment, the authentication server <b>200</b> periodically acquires an authentication success rate of the User<b>0001</b> for the previous one month (December) from the authentication log, and finds that the authentication success rate is 30%. Since the authentication success rate is lower than an authentication success rate of 40%, which is a system defined threshold, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table to local authentication.
0064At the time of authentication, the User<b>0001</b> inputs a user ID and fingerprint data from the client <b>100</b>. The client <b>100</b> transmits the user ID and fingerprint data for verification to the authentication server <b>200</b>. The authentication server <b>200</b> determines, based on the user ID transmitted from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0001</b>. The authentication server <b>200</b> refers to the local-authenticated-user flag <b>310</b> of the User<b>0001</b> in the user management table <b>300</b>, and determines that local authentication is to be performed. The authentication server <b>200</b> transmits the user ID, the biometric data for verification, and a registered template to the client <b>100</b>. The client <b>100</b> performs a verification process.
0065In March, when the state of the finger of the User<b>0001</b> returns to a normal state from a dry state and when the authentication success rate becomes high, the authentication server <b>200</b> acquires an authentication success rate for the previous one month (February) from the authentication log, and finds that the authentication success rate is 50%. Since the authentication success rate is over a system defined authentication success rate of 40%, the authentication server <b>200</b> changes the local-authenticated-user flag <b>310</b> of the User<b>0001</b> in the user management table <b>300</b> to server authentication.
0066At the time of authentication, the User<b>0001</b> inputs a user ID and fingerprint data from the client <b>100</b>. The client <b>100</b> transmits the user ID and fingerprint data for verification to the authentication server <b>200</b>. The authentication server <b>200</b> determines, based on the user ID transmitted from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0001</b>. The authentication server <b>200</b> refers to the local-authenticated-user flag <b>310</b> of the User<b>0001</b> in the user management table <b>300</b>, and determines that server authentication is to be performed. The authentication server <b>200</b> refers to the registered fingerprint template <b>304</b> in the user management table <b>300</b> held in the authentication server <b>200</b>, and performs a verification process with the biometric data for verification, which has been transmitted from the client <b>100</b>. The authentication server <b>200</b> transmits an authentication result to the client <b>100</b>.
0067An embodiment in which the client <b>100</b> determines whether to perform local authentication or server authentication will be described. If it is assumed that the current month is January, the finger of the User<b>0001</b> is dry, and the authentication success rate in December is reduced to 30%. Upon receipt of an authentication request from the User<b>0001</b>, the authentication server <b>200</b> performs a pattern matching process in addition to verification based on only minutiae points to verify the identity of the User<b>0001</b>. Accordingly, if an authentication request is issued from the User<b>0001</b>, the length of the authentication process time increases, leading to an increased load on the authentication server <b>200</b>.
0068In this embodiment, the authentication server <b>200</b> periodically acquires the authentication success rate of the User<b>0001</b> for the previous one month (December), i.e., “30%”, from the authentication log. Since the authentication success rate is lower than an authentication success rate of 40%, which is a system defined threshold, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>300</b> to local authentication.
0069The authentication server <b>200</b> periodically refers to the client management table <b>500</b>, and finds that the client <b>100</b> (Client<b>0002</b>) is used by the User<b>0001</b>, User<b>0002</b>, and User<b>0003</b>. The authentication server <b>200</b> extracts user information about the User<b>0001</b>, the User<b>0002</b>, and the User<b>0003</b> from the client management table <b>500</b>, and transmits the user information to the Client<b>0002</b>, thereby allowing the client <b>100</b> (Client<b>0002</b>) to update the user management table <b>300</b> and hold the updated user management table <b>300</b>.
0070At the time of authentication, the User<b>0001</b> inputs a user ID and fingerprint data from the client <b>100</b> (Client<b>0002</b>). The client <b>100</b> determines, based on the user ID input from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0001</b>. The client <b>100</b> (Client<b>0002</b>) refers to the local-authenticated-user flag <b>310</b> of the User<b>0001</b> in the user management table <b>300</b> owned by the client <b>100</b> (Client<b>0002</b>), and determines that local authentication is to be performed. The client <b>100</b> (Client<b>0002</b>) extracts a registered template for the User<b>0001</b> from the user management table <b>300</b>, and performs a verification process with the biometric data for verification.
0071In March, when the state of the finger of the User<b>0001</b> returns to a normal state from a dry state and when the authentication success rate becomes high, the authentication server <b>200</b> acquires the authentication success rate for the previous one month (February), i.e., “50%”, from the authentication log. Since the authentication success rate is over a system defined authentication success rate of 40%, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>300</b> to server authentication. The authentication server <b>200</b> periodically refers to the client management table <b>500</b>, and finds that the client <b>100</b> (Client<b>0002</b>) is used by the User<b>0001</b>, the User<b>0002</b>, and the User<b>0003</b>. The authentication server <b>200</b> extracts user information about the User<b>0001</b>, the User<b>0002</b>, and the User<b>0003</b> from the client management table <b>500</b>, and transmits the user information to the Client<b>0002</b>. This allows the client <b>100</b> (Client<b>0002</b>) to update the user management table <b>300</b> and hold the updated user management table <b>300</b>. Here, the local-authenticated-user flag of the User<b>0001</b>, which is held in the client <b>100</b> (Client<b>0002</b>), is changed from local authentication to server authentication.
0072At the time of authentication, the User<b>0001</b> inputs a user ID and fingerprint data from the client <b>100</b> (Client<b>0002</b>). The client <b>100</b> determines, based on the user ID input from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0001</b>. The client <b>100</b> (Client<b>0002</b>) refers to the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>300</b> held therein, and determines that server authentication is to be performed. The client <b>100</b> (Client<b>0002</b>) transmits the user ID and the biometric data for verification to the authentication server <b>200</b>. The authentication server <b>200</b> refers to the registered template for the User<b>0001</b> from the user management table, and performs a verification process with the data for verification. The authentication server <b>200</b> transmits an authentication result to the client <b>100</b> (Client<b>0002</b>), and also saves the authentication result in the authentication server <b>200</b> as a log.
0073An embodiment in which it is determined whether to perform local authentication or server authentication in accordance with the quality of the registered template will be described. It is assumed that the User<b>0001</b> registers a registered fingerprint template in the authentication server <b>200</b> in December, when the finger is dry and is not suitable for fingerprint authentication, and that the registration quality is “4”. The authentication server <b>200</b> periodically refers to the user management table <b>300</b>, and changes the setting of a user for which the registration quality is less than or equal to a system defined threshold of “5” for registration quality to local authentication. The registered template for the User<b>0001</b> as of January was registered in December, and the registration quality is “4”. Thus, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>300</b> to local authentication. It is assumed that the check of the registration quality and the changing of the local-authenticated-user flag can also be performed when a user registers fingerprint data. Subsequently, the process for local authentication is performed in a way similar to that of the process described above.
0074An embodiment for providing dynamic changing between server authentication and local authentication on a client-by-client basis will be described. The authentication server <b>200</b> periodically calculates the authentication success rate of each client from the log <b>400</b> of verification results, and determines that local authentication is to be performed if the authentication success rate is less than or equal to a system defined threshold, and that server authentication is to be performed if the authentication success rate is greater than or equal to the threshold. The client management table <b>700</b> manages local authentication flags on a client-by-client basis. The Client<b>0002</b> is assigned local authentication.
0075At the time of authentication, a user inputs a user ID and fingerprint data from the client <b>100</b>. The client <b>100</b> transmits the user ID, fingerprint data for verification, and the client name (Client<b>0002</b>) to the authentication server <b>200</b>. The authentication server <b>200</b> determines, based on the client name (Client<b>0002</b>) transmitted from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0001</b>. The authentication server <b>200</b> refers to the local-authenticated-user flag of the Client<b>0002</b> in the client management table <b>700</b>, and determines that local authentication is to be performed. Subsequently, local authentication is performed using a method similar to the method described above.
0076Additionally, for example, the IP address of the client <b>100</b> may also be used if it is information capable of uniquely identifying the client. In addition, the authentication server <b>200</b> may transmit information about the client management table <b>700</b> to the client <b>100</b> in advance, and, at the time of authentication, the client <b>100</b> may determine whether to perform local authentication or server authentication by using the client <b>100</b> information.
0077An embodiment in which it is determined whether to perform local authentication or server authentication in accordance with the quality of data for verification will be described. The User<b>0001</b> inputs a user ID and fingerprint data from the client <b>100</b>. The client <b>100</b> creates data for verification, and transmits the data for verification together with the user ID to the authentication server <b>200</b>. It is assumed that, as a result of the authentication server <b>200</b> having acquired the quality value of the data for verification from the data for verification of the User<b>0001</b> transmitted from the client <b>100</b>, the quality value is “4”. If the system defines that the quality value is less than or equal to a threshold of “5” for data for verification as a condition where the setting is changed to local authentication, the authentication server <b>200</b> determines that local authentication is to be performed, and transmits the user ID, the biometric data for verification, and the registered template to the client <b>100</b>. The client <b>100</b> performs a fingerprint verification process.
0078An embodiment in which the client <b>100</b> performs user data management will be described. It is assumed that the client <b>100</b> periodically receives the user management table <b>300</b> from the authentication server <b>200</b> and holds the user management table <b>300</b>. After that, the client <b>100</b> periodically refers to the local-authenticated-user flag in the user management table <b>300</b> owned by the client <b>100</b>. Since the User<b>0001</b> is a user to be authenticated with local authentication, the registered fingerprint template, fingerprint data type, and registration quality about the User<b>0001</b> are downloaded from the authentication server <b>200</b>. Then, the client <b>100</b> updates the user management table <b>300</b> held in the client <b>100</b>.
0079An embodiment in which local authentication is performed using transformed registered data will be described. At the time of authentication, the User<b>0001</b> inputs a user ID and fingerprint data from the client <b>100</b>. The client <b>100</b> transmits the user ID and fingerprint data for verification to the authentication server <b>200</b>. The authentication server <b>200</b> determines, based on the user ID transmitted from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0001</b>. The authentication server <b>200</b> refers to the local-authenticated-user flag <b>614</b> of the User<b>0001</b> in the user management table <b>600</b>, and determines that local authentication is to be performed. The authentication server <b>200</b> transforms the data for verification using a transformation key (AhAoAfA14) for the User<b>0001</b> in the user management table <b>600</b>.
0080Then, the authentication server <b>200</b> transmits the user ID, the transformed biometric data for verification, and the transformed registered template to the client <b>100</b>. The client <b>100</b> performs a verification process between the transformed biometric data for verification and the transformed registered template. Meanwhile, at the time of authentication, the User<b>0002</b> inputs a user ID and fingerprint data from the client <b>100</b>, and transmits the user ID and fingerprint data for verification from the client <b>100</b> to the authentication server <b>200</b>.
0081The authentication server <b>200</b> determines, based on the user ID transmitted from the client <b>100</b>, whether to perform local authentication or server authentication on the User<b>0002</b>. Thus, the authentication server <b>200</b> refers to the local-authenticated-user flag of the User<b>0002</b> in the user management table <b>600</b>, and determines that server authentication is to be performed. After that, the authentication server <b>200</b> performs a verification process between the data for verification, which has been transmitted from the client, and the registered template for the User<b>0002</b> in the user management table <b>600</b>.
0082An embodiment in which user data is managed when local authentication is performed using transformed registered data will be described. The authentication server <b>200</b> calculates an authentication success rate of the User<b>0001</b> for the previous one month (December), that is, “30%”. Since the authentication success rate is lower than an authentication success rate of “40%”, which is a system defined threshold, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>600</b> to local authentication. In this case, the transformation key creation unit creates a transformation key for the User<b>0001</b>, transforms the registered template in the user management table <b>600</b>, and stores the resulting registered template in the user management table <b>600</b>.
0083In March, when the state of the finger of the User<b>0001</b> returns to a normal state from a dry state and when the authentication success rate becomes high, the authentication server <b>200</b> acquires the authentication success rate of the User<b>0001</b> for the previous one month (February), i.e., “50%”, from the authentication log. Since the authentication success rate is over an authentication success rate of “40%”, which is a system defined threshold, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>600</b> to server authentication. In this case, the authentication server <b>200</b> deletes the transformation key for the User<b>0001</b> and the transformed registered template from the user management table <b>600</b>.
0084An embodiment in which the client <b>100</b> manages user data when performing local authentication using transformed registered data will be described. It is assumed that the client <b>100</b> periodically receives the user management table <b>600</b> from the authentication server <b>200</b> and owns the user management table <b>600</b>. Then, the client <b>100</b> periodically refers to the user management table <b>600</b> owned by the client <b>100</b>, and refers to the local-authenticated-user flag. Since the User<b>0001</b> is a user to be authenticated with local authentication, the client <b>100</b> downloads the transformed registered fingerprint template, fingerprint data type, registration quality, and transformation key about the User<b>0001</b> from the authentication server <b>200</b>. The client <b>100</b> updates the user management table <b>600</b> owned by the client <b>100</b>.
0085In March, when the state of the finger of the User<b>0001</b> returns to a normal state from a dry state and when the authentication success rate becomes high, the authentication server <b>200</b> acquires the authentication success rate of the User<b>0001</b> for the previous one month (February), i.e., “50%”, from the authentication log. Since the authentication success rate is over a system defined authentication success rate of 40%, the authentication server <b>200</b> changes the local-authenticated-user flag of the User<b>0001</b> in the user management table <b>600</b> to server authentication. Then, the client <b>100</b> periodically refers to the user management table <b>600</b> held therein, refers to the local-authenticated-user flag, and detects that the User<b>0001</b> has been changed from a user to be authenticated with local authentication to that with server authentication. The client <b>100</b> deletes the transformation key and the transformed registered template from the user management table <b>600</b> owned by the client <b>100</b>.
0086<figref idref="DRAWINGS">FIG. 12</figref> illustrates a flowchart of an authentication process according to this embodiment. In S<b>101</b>, at the time of authentication, a user inputs a user ID and biometric data from the client <b>100</b>. It is assumed that the biometric data is input from a biometric sensor connected to the client <b>100</b>. The process proceeds to S<b>102</b>.
0087In S<b>102</b>, the client <b>100</b> generates biometric data for verification from the input biometric data. The process proceeds to S<b>103</b>.
0088In S<b>103</b>, the client <b>100</b> transmits the user ID and the generated biometric data for verification to the authentication server <b>200</b>. The process proceeds to S<b>104</b>.
0089In S<b>104</b>, the authentication server <b>200</b> refers to the user management table <b>300</b> on the basis of the user ID transmitted from the client <b>100</b>. The process proceeds to S<b>105</b>.
0090In S<b>105</b>, the authentication server <b>200</b> determines whether to perform local authentication or server authentication. If it is determined that local authentication is to be performed, the process proceeds to S<b>106</b>. On the other hand, if it is determined that server authentication is to be performed, the process proceeds to S<b>108</b>.
0091In S<b>106</b>, the authentication server <b>200</b> performs a verification process between the biometric data for verification and a registered template. Then, the authentication server <b>200</b> determines whether or not the degree of matching between the biometric data for verification and the registered template, which has been calculated in the verification process, is greater than or equal to a predetermined value. If the degree of matching is greater than or equal to the predetermined value, the authentication server <b>200</b> determines that authentication has succeeded. On the other hand, if the degree of matching is not greater than or equal to the predetermined value, the authentication server <b>200</b> determines that authentication has failed. The authentication server <b>200</b> transmits an authentication result to the client <b>100</b>. The process proceeds to S<b>107</b>.
0092In S<b>107</b>, the authentication server <b>200</b> saves the authentication result as a log. The process ends.
0093In S<b>108</b>, the authentication server <b>200</b> transmits the user ID, the biometric data for verification, and the registered template to the client <b>100</b>. The process proceeds to S<b>109</b>.
0094In S<b>109</b>, the client <b>100</b> performs a verification process between the biometric data for verification and the registered template. Then, the client <b>100</b> determines whether or not the degree of matching between the biometric data for verification and the registered template, which has been calculated in the verification process, is greater than or equal to a predetermined value. If the degree of matching is greater than or equal to the predetermined value, the client <b>100</b> determines that authentication has succeeded. On the other hand, if the degree of matching is not greater than or equal to the predetermined value, the client <b>100</b> determines that authentication has failed. The process proceeds to S<b>110</b>.
0095In S<b>110</b>, the client <b>100</b> transmits an authentication result to the authentication server <b>200</b> in a way synchronous or asynchronous to the authentication time. The process proceeds to S<b>107</b>, in which the authentication server <b>200</b> saves the authentication result obtained when local authentication is performed as a log. The process ends.
0096<figref idref="DRAWINGS">FIG. 13</figref> illustrates a flowchart of an authentication process according to this embodiment. In S<b>201</b>, at the time of authentication, a user inputs a user ID and biometric data from the client <b>100</b>. It is assumed that the biometric data is input from a biometric sensor connected to the client <b>100</b>. The process proceeds to S<b>202</b>.
0097In S<b>202</b>, the client <b>100</b> generates biometric data for verification from the input biometric data. The process proceeds to S<b>203</b>.
0098In S<b>203</b>, the client <b>100</b> refers to the user management table <b>300</b> held in the client <b>100</b> on the basis of the input user ID. The process proceeds to S<b>204</b>.
0099In S<b>204</b>, as a result of the reference to the user management table <b>300</b>, the client <b>100</b> determines whether or not the corresponding user is found. If the corresponding user is found, the process proceeds to S<b>205</b>. On the other hand, if the corresponding user is not found, the process proceeds to S<b>206</b>.
0100In S<b>205</b>, if the corresponding user information is in the client <b>100</b>, the client <b>100</b> refers to the local-authenticated-user flag <b>310</b> the user management table <b>300</b>, and determines whether to perform local authentication or server authentication. If local authentication is to be performed, the process proceeds to S<b>208</b>. On the other hand, if server authentication is to be performed, the process proceeds to S<b>206</b>.
0101In S<b>208</b>, the client <b>100</b> performs a verification process. The verification process of the client <b>100</b> is similar to the process described above, and a description thereof is thus omitted. The process proceeds to S<b>209</b>.
0102In S<b>209</b>, the client <b>100</b> transmits an authentication result to the authentication server <b>200</b>. The process proceeds to S<b>210</b>.
0103In S<b>210</b>, the authentication server <b>200</b> saves the authentication result transmitted from the client <b>100</b>. The process ends.
0104In S<b>206</b>, the client <b>100</b> transmits the user ID and the data for verification to the authentication server <b>200</b>. The process proceeds to S<b>207</b>.
0105In S<b>207</b>, the authentication server <b>200</b> performs a verification process. The verification process of the authentication server <b>200</b> is similar to the process described above, and a description thereof is thus omitted. The process proceeds to S<b>210</b>.
0106<figref idref="DRAWINGS">FIG. 14</figref> illustrates a flowchart of an authentication process when cancelable biometric authentication is applied during local authentication. In S<b>301</b>, at the time of authentication, a user inputs a user ID and biometric data from the client <b>100</b>. The process proceeds to S<b>302</b>.
0107In S<b>302</b>, the client <b>100</b> generates biometric data for verification from the input biometric data. The process proceeds to S<b>303</b>.
0108In S<b>303</b>, the client <b>100</b> transmits the user ID and the biometric data for verification to the authentication server <b>200</b>. The process proceeds to S<b>304</b>.
0109In S<b>304</b>, the authentication server <b>200</b> refers to the user management table <b>600</b> on the basis of the user ID transmitted from the client <b>100</b>. The process proceeds to S<b>305</b>.
0110In S<b>305</b>, the authentication server <b>200</b> determines whether to perform local authentication or server authentication. If it is determined that local authentication is to be performed, the process proceeds to S<b>308</b>. On the other hand, if it is determined that server authentication is to be performed, the process proceeds to S<b>308</b>.
0111In S<b>306</b>, the authentication server <b>200</b> performs a verification process. The verification process of the authentication server <b>200</b> is similar to the process described above, and a description thereof is thus omitted. The process proceeds to S<b>307</b>.
0112In S<b>307</b>, the authentication server <b>200</b> saves an authentication result. The process ends.
0113In S<b>308</b>, the authentication server <b>200</b> transforms the data for verification using the transformation key <b>608</b> in the user management table <b>600</b>. The process proceeds to S<b>309</b>.
0114In S<b>309</b>, the authentication server <b>200</b> transmits the user ID, the transformed biometric data for verification, and the transformed registered template to the client <b>100</b>. The process proceeds to S<b>310</b>.
0115In S<b>310</b>, the client <b>100</b> performs a verification process. The verification process of the client <b>100</b> is similar to the process described above, and a description thereof is thus omitted. The process proceeds to S<b>311</b>.
0116In S<b>311</b>, the client <b>100</b> transmits an authentication result to the authentication server <b>200</b> in a way synchronous or asynchronous to the authentication time. The process proceeds to S<b>307</b>.
0117Cancelable biometric authentication can also be applied to an authentication process in which the client <b>100</b> holds the user management data <b>600</b>.
0118According to this embodiment, the following advantageous effects are achievable. A user for which a long verification process time is required because of the difficulty to verify their fingerprint is authenticated using local authentication, thereby speeding up the authentication process time. A user for which a large amount of computation is required for a fingerprint verification process is authenticated using local authentication, thereby enabling a reduction of the load on the authentication server. The switching between local authentication and server authentication is automatic, thus reducing time and effort required for the system administrator to perform operation management activities. Since authentication is performed using transformed fingerprint template data when switching to local authentication is made, the transformation key is altered and the fingerprint template data is re-registered when the fingerprint data leaks, and unauthorized access can be prevented.
0119In addition, a plurality of distributed servers connected to an authentication server may perform a verification process on a user for which the authentication success rate is less than or equal to a certain value.
0120According to an aspect of this embodiment, in a client-server biometric authentication system, the load on a server can be reduced when user processing with a low authentication success rate is performed.
0121As mentioned above, the present invention has been specifically described for better understanding of the embodiments thereof and the above description does not limit other aspects of the invention. Therefore, the present invention can be altered and modified in a variety of ways without departing from the gist and scope thereof.
0122All examples and conditional language recited herein are intended for pedagogical purposes to aid the reader in understanding the invention and the concepts contributed by the inventor to furthering the art, and are to be construed as being without limitation to such specifically recited examples and conditions, nor does the organization of such examples in the specification relate to a showing of the superiority and inferiority of the invention. Although the embodiments of the present inventions have been described in detail, it should be understood that the various changes, substitutions, and alterations could be made hereto without departing from the spirit and scope of the invention.
Contents6
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2014072188A1 | Cited by | United States of America | Pre-grant |
| EP0935221A2 | Cites | European Patent Office (EPO) | Applicant |
| EP1890233A1 | Cites | European Patent Office (EPO) | Applicant |
| JP2001256191A | Cites | Japan | Applicant |
| AU2004254771A1 | Cites | Australia | Applicant |
| JP2004318756A | Cites | Japan | Applicant |
| JP2005182641A | Cites | Japan | Applicant |
| US2008031496A1 | Cites | United States of America | Applicant |
| JP2008040763A | Cites | Japan | Applicant |
| JP2008065835A | Cites | Japan | Applicant |
| US2008172725A1 | Cites | United States of America | Applicant |
| JP2008176407A | Cites | Japan | Applicant |
| US6928547B2 | Cites | United States of America | Search report |
| JPH09288648A | Cites | Japan | Applicant |
| JPH11224236A | Cites | Japan | Applicant |
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2009004775 | Japan | W | |
| 2009004775 | Japan | W | |
| PCTJP2009004775 | – | – | – |
| WO2009JP04775 | – | – | – |
74 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Email NotificationEML_NTR | EML_NTR | |
| Mailing Corrected Notice of AllowabilityMCNOA | MCNOA | |
| Corrected Notice of AllowabilityCNOA | CNOA | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Workflow - Request for RCE - FinishFRCE | FRCE | |
| Workflow - Request for RCE - FinishFRCE | FRCE | |
| Quick Path IDS RequestQPREQ | QPREQ | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Mail-Record Petition Decision of Granted to Withdraw from IssueMP006 | MP006 | |
| Record Petition Decision of Granted to Withdraw from IssueP006 | P006 | |
| Petition EnteredPET. | PET. | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Printer Rush- No mailingTCPB | TCPB | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Amendment after Notice of Allowance (Rule 312)AllowedA.NA | A.NA | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Interview Summary - Examiner InitiatedEXIE | EXIE | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Sent to Classification ContractorPGPC | PGPC | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Cleared by OIPE CSRL194 | L194 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.)FEPP | FEPP | |
| AssignmentAS | AS |
Numbers
- Publication
- 08863259
- Publication, DOCDB
- 8863259
- Publication, EPODOC
- US8863259
- Application
- 13406953
- Application, DOCDB
- 201213406953
- Application, EPODOC
- US201213406953
Titles
- English
- Method of controlling biometric authentication system, non-transitory, computer readable storage medium and biometric authentication system
Patent term adjustment
- Applicant delay
- −96 days
- Net adjustment
- 0 days
Classification
- CPC, 3
- G06F21/32
- G06V40/1365
- G06V10/993
- IPC, 2
- H04L29 00
- G06F21 32
- USPC, 2
- 726007000
- 713186000